Headers, certificates and browser hardening
HSTS, CSP, frame control, referrer policy, transport configuration and common public security headers.
A fixed-scope, low-touch external review of public-facing web, DNS, email trust and exposed security signals. Delivered as a written report with priority, evidence and plain-English remediation.
Owner, priority, recommended fix, validation step and business impact for each finding.
The snapshot is designed for teams that need a practical external view quickly, without intrusive testing or enterprise consultancy overhead.
HSTS, CSP, frame control, referrer policy, transport configuration and common public security headers.
SPF, DKIM, DMARC, CAA and public DNS signals that affect spoofing resistance and trust.
Visible admin routes, WordPress surface, staging clues and public technology signals that may need tightening.
No fake dashboards or stock proof. The output is a practical written snapshot with evidence, severity, remediation and boundaries clear enough for a founder, agency or technical team to act on.
The External Security Snapshot is a lightweight external review. It is intentionally narrow, lawful and non-intrusive.
Shows document control, limitations, severity, evidence and action planning.
Each finding is written with enough evidence to understand the issue and enough practical guidance to fix or delegate it without translating security jargon.
Use the form with the domain, company and context for the review.
The exact public-facing target and boundaries are agreed in writing.
Payment link or invoice is sent only after written scope approval.
You receive the written report with findings and remediation priorities, usually within 48 hours where scope is suitable.
No commitment at this stage. I will reply with scope, timing and next steps if the request fits the snapshot model.